$90/query re-embed → ~$400/mo, ~1 sec, no egress by design
The situation
3M+ regulated records, nightly-batch export only, capped budget
Hard rule: data never leaves the client's AWS account
Manual analyst search was slow and missed matches
What we delivered
In-perimeter RAG on Bedrock, row-level access from Cognito/JWT
Nightly hash-diff embedding, hybrid pgvector retrieval (3M → ~100)
Cited, human-in-the-loop answers, read-only on the source
Architecture delivered end to end. Runtime figures are design targets.